MarketaLog in

Privacy Policy

Version 2026-09-27

This Privacy Policy explains how [company name not set] (“Marketa”, “we”, “us”) collects, uses and protects personal data when you use Marketa, our website and our services, and what choices you have. It should be read with our Terms of Service. We handle personal data in line with Qatar’s Personal Data Privacy Protection Law (Law No. 13 of 2016) and other laws that apply to us.

1. Our role: controller and processor

  • Controller. For your own account, your login, your billing and how you use Marketa, we decide why and how the data is used, so we are the controller.
  • Processor. For information about your customers, leads and website visitors that you put into Marketa or collect through it (for example chatbot and WhatsApp conversations, CRM records), you are the controller and we process it on your instructions to provide the service. You are responsible for telling those people how their data is used and for having any consent you need.

2. What we collect

  • Account data: your name, email address and a hashed password (we never store your password in readable form), email-verification and password-reset tokens, and your workspace memberships and roles.
  • Workspace data you provide: company, brand, product and audience details; knowledge documents, FAQs and guidelines; content, creatives and uploaded images; campaigns, automations, experiments and settings.
  • Customer and lead data: names, emails, phone numbers, notes, deals, and the messages exchanged with your website chatbot or WhatsApp, including the page a visitor was on when they chatted and whether they opted out.
  • Usage and AI data: what you ask the AI to do and the context sent with it, counts of AI calls, and an audit log of important actions (who did what and when, with the IP address of the request).
  • Billing data: your plan, subscription status and a Stripe customer reference. Card details are entered on Stripe’s pages and are not seen or stored by us.
  • Website enquiries: if you use our homepage web-design form, the contact details, project information, links or files and marketing preferences you submit, and the time you gave consent.
  • Homepage analytics: anonymous counts of homepage actions (an event name and language). These do not identify you and are not linked to an account.
  • Technical data: IP address, browser type and request logs kept by our hosting provider, and error reports.

3. How we use it

  • To provide, secure and improve Marketa, including drafting content, answering customers and running your automations;
  • to create and manage your account, take payment and send service messages (verification, password reset, billing and security notices, notifications you set up);
  • to prevent abuse and fraud, enforce usage limits and our Terms, and keep records we are required to keep;
  • to respond to your enquiries, including web-design requests, and, where you agreed, to tell you about our services.

We do not sell personal data, and we do not use it for third-party advertising.

4. Consent and other grounds

We process personal data where you have given consent (for example on the web-design form), where it is needed to provide the service you asked for, where we have a legitimate interest in running and securing the service in a way that does not override your rights, or where the law requires it. You can withdraw consent at any time; this does not affect processing already carried out.

5. AI processing

To generate text, plans, chatbot replies and images, Marketa sends the relevant request and business context (and, for the chatbot, the visitor’s message) to the AI providers listed below. We send what is needed for the task. The providers process it under their own terms. Please do not put sensitive personal data, such as health, financial account or government identity details, into prompts, knowledge documents or messages you do not want processed by these providers.

6. Who we share data with

We use the following service providers. Optional ones are used only when the feature is switched on for the workspace.

ProviderWhat forData involved
VercelHosting and running the applicationAll data in transit; request logs (IP address, browser)
NeonManaged PostgreSQL databaseAll account and workspace data at rest
Anthropicwhen enabledAI text generation (content, chatbot replies, plans)The business context and prompts sent for each AI request, including visitor messages the chatbot answers
OpenAIwhen enabledAI image generationImage prompts you write
Stripewhen enabledPayment processing and invoicesName, email, plan and payment details (card data is handled by Stripe and never reaches us)
Resendwhen enabledSending email (verification, password reset, notifications)Recipient email address and message content
Upstashwhen enabledRate limiting to prevent abuseIP addresses and request counts, briefly
Sentrywhen enabledError monitoringError details, which may include page URLs and technical identifiers
Meta (WhatsApp, Facebook, Instagram)when enabledMessaging and publishing when you connect these channelsMessages, contact phone numbers and posts you send or publish through them
LinkedIn, TikTok and Google (advertising)when enabledPublishing and ads when you connect these channelsPosts, ad content and account identifiers you send through them
S3-compatible storage providerwhen enabledStoring uploaded and generated imagesImage files you upload or generate

We may also disclose data where the law or a competent authority requires it, or to protect rights and safety, and to a successor if the business is transferred (with the same protections).

7. Where data is processed

Our providers may store and process data outside Qatar. Where personal data leaves Qatar we take reasonable steps, including contractual commitments from providers, so that it continues to be protected to an appropriate standard.

8. How long we keep it

We keep account and workspace data while your account is active. If you ask us to delete it, or your account ends, we delete or anonymise it within a reasonable period, except for records we must keep by law or for legitimate purposes such as security logs, tax and billing records, and backups, which are removed on their normal cycle. Anonymous homepage analytics are kept without a personal link. Contact us to request deletion or an export.

9. Security

We protect data with encryption in transit, hashed passwords, separation between customer workspaces, role-based access and audit logging, and we limit who at Marketa can access data. No system is perfectly secure; if a breach affects your personal data we will notify you and the authorities as the law requires.

10. Your rights

Subject to the law, you can ask us to give you access to your personal data, correct it, delete it, stop or restrict certain processing, or withdraw consent. If we process your customers’ data for you, please direct requests to the business that collected it; we will help them respond. To exercise a right, write to [contact email not set]. We will respond within a reasonable time. You may also complain to the competent data-protection authority in Qatar.

11. Cookies and similar technologies

  • Session cookie (marketa_session): keeps you signed in. Essential; it is removed when you log out or it expires.
  • Language cookie (marketa_lang): remembers whether you chose English or Arabic.
  • Theme setting (stored in your browser): remembers light or dark mode.

We do not use advertising or cross-site tracking cookies. The website chatbot on a customer’s own site may store a random visitor identifier in the visitor’s browser to keep a conversation together.

12. Children

Marketa is for businesses and is not directed at anyone under 18. We do not knowingly collect personal data from children.

13. Changes to this policy

We may update this policy. If a change is material we will tell you by email or in the app before it takes effect. The version date at the top shows when the current text was published.

14. Contact

For privacy questions or requests: [contact email not set].